RHSA-2026:36105HighCVSS 8.8

Red Hat Security Advisory: Assisted Installer RHEL 8 components for Multicluster Engine for Kubernetes 2.6.12

Published
July 7, 2026
Last Modified
September 25, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions CVE-2026-53488 — github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin

🎯 Affected products13

  • multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/assisted-installer-controller-rhel8@sha256:13af28ec463e2877e106c0f36881e26033532a7681a282de6b988d2cddf74f7d_ppc64le as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/assisted-installer-controller-rhel8@sha256:15066fae8152efb67cd9f839af234cb21d1f88e3d75c0419c0563c5d0f1dd692_amd64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/assisted-installer-controller-rhel8@sha256:2cbf7b3ece78f963ffb9fc60b2ecf4c4440361750d4d3964142ef8bdac527379_arm64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/assisted-installer-controller-rhel8@sha256:887035814ff7e6e0ff72019eed37277aa535389de65971fd6a4fac3acd32a84c_s390x as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/assisted-installer-rhel8@sha256:26ba753fd18a3d966755a548331401e68abc2791a077ad370f2a955a32d7677f_arm64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/assisted-installer-rhel8@sha256:6e76d785acd383c4123195401363e1c4a9ea00fba18a25bc4ef98f33f29c5083_s390x as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/assisted-installer-rhel8@sha256:99978f203298eee00bf5eb951506630115d1e9afae26469c98ff6cd271a4d1fe_ppc64le as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/assisted-installer-rhel8@sha256:b1eb0d2804359d83c18c8eec4dc663001b7f89e954a31fd2c47053c27cb4437e_amd64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/assisted-service-8-rhel8@sha256:26ab409373069765e56e7b056702ac3d5e527191da6937e547fe4ab934fac1e4_arm64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/assisted-service-8-rhel8@sha256:7d2d22ecbe79b676d7e08eb9675645212f06b1975bf6b320a53f2c83913e79dd_ppc64le as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/assisted-service-8-rhel8@sha256:9c57a27b244c777a94846abc3c7738efe972ae1d39453bc6363a417a6587f1d9_amd64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/assisted-service-8-rhel8@sha256:a7ed7fb0b19759c868ff4c6453753b2d80596802c182b5da76e6ff706fc18551_s390x as a component of multicluster engine for Kubernetes 2.6

✅ Remediation

For more information about Assisted Installer, see the following documentation: https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.11/html/clusters/cluster_mce_overview#cim-intro For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.11/html/clusters/cluster_mce_overview#mce-install-intro This documentation will be available after the general availability release of Red Hat Advanced Cluster Management 2.11. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Restrict container image pulls to trusted registries using admission policies or image signature verification. Where containerd is used as the container runtime, disable or restrict the binary:// logger URI scheme in the containerd configuration to prevent the label-to-logger attack path.

🔗 References (6)